When using Clearpass with TACACS there is an "aruba:common" dictionary attribute called "Aruba-Admin-Role"
Those roles are pre-configured on the Controllers [i.e. root, read-only, guest-provisioning, etc]
The specific value that would likely fit your scenario would be: "network-operations"
You would need to configure that TACACS VSA as a part of your Enforcement Profile that is triggered for those helpdesk users.
------------------------------
If my post was useful, please Accept Solution and Give Kudos.
------------------------------
Zak Chalupka
Principal Engineer - HPE Aruba
ACDX | ACMP | ACSP | ACCP
wifizak@hpe.com------------------------------
Ideas expressed here are solely my own and not necessarily that of HPE Aruba.
------------------------------